CVE-2010-0195: Code Injection
Published Apr 14, 2010
·Updated
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, do not properly handle fonts, which allows attackers to execute arbitrary code via unspecified vectors.
Affected Software
76 affected components
Adobe Acrobat=9.0
Adobe Acrobat=9.1
Adobe Acrobat=9.1.1
Adobe Acrobat=9.1.2
Adobe Acrobat=9.1.3
Adobe Acrobat=9.2
Adobe Acrobat=9.3
Adobe Acrobat=9.3.1
Adobe Acrobat Reader=9.0
Adobe Acrobat Reader=9.1
Adobe Acrobat Reader=9.1.1
Adobe Acrobat Reader=9.1.2
Adobe Acrobat Reader=9.1.3
Adobe Acrobat Reader=9.2
Adobe Acrobat Reader=9.3
Adobe Acrobat Reader=9.3.1
Apple iOS and macOS
Microsoft Windows
Adobe Acrobat=8.0
Adobe Acrobat=8.1
Adobe Acrobat=8.1.1
Adobe Acrobat=8.1.2
Adobe Acrobat=8.1.3
Adobe Acrobat=8.1.4
Adobe Acrobat=8.1.5
Adobe Acrobat=8.1.6
Adobe Acrobat=8.1.7
Adobe Acrobat=8.2
Adobe Acrobat=8.2.1
Adobe Acrobat Reader=8.0
Adobe Acrobat Reader=8.1
Adobe Acrobat Reader=8.1.1
Adobe Acrobat Reader=8.1.2
Adobe Acrobat Reader=8.1.4
Adobe Acrobat Reader=8.1.5
Adobe Acrobat Reader=8.1.6
Adobe Acrobat Reader=8.1.7
Adobe Acrobat Reader=8.2.1
All of the following
Any of the following
Adobe Acrobat=9.0
Adobe Acrobat=9.1
Adobe Acrobat=9.1.1
Adobe Acrobat=9.1.2
Adobe Acrobat=9.1.3
Adobe Acrobat=9.2
Adobe Acrobat=9.3
Adobe Acrobat=9.3.1
Adobe Acrobat Reader=9.0
Adobe Acrobat Reader=9.1
Adobe Acrobat Reader=9.1.1
Adobe Acrobat Reader=9.1.2
Adobe Acrobat Reader=9.1.3
Adobe Acrobat Reader=9.2
Adobe Acrobat Reader=9.3
Adobe Acrobat Reader=9.3.1
Microsoft Windows
All of the following
Any of the following
Adobe Acrobat=8.0
Adobe Acrobat=8.1
Adobe Acrobat=8.1.1
Adobe Acrobat=8.1.2
Adobe Acrobat=8.1.3
Adobe Acrobat=8.1.4
Adobe Acrobat=8.1.5
Adobe Acrobat=8.1.6
Adobe Acrobat=8.1.7
Adobe Acrobat=8.2
Adobe Acrobat=8.2.1
Adobe Acrobat Reader=8.0
Adobe Acrobat Reader=8.1
Adobe Acrobat Reader=8.1.1
Adobe Acrobat Reader=8.1.2
Adobe Acrobat Reader=8.1.4
Adobe Acrobat Reader=8.1.5
Adobe Acrobat Reader=8.1.6
Adobe Acrobat Reader=8.1.7
Adobe Acrobat Reader=8.2.1
Microsoft Windows
Remediation
Patch Available
Event History
Apr 14, 2010
CVE Published
via MITRE·03:44 PM
Data Sourced
via MITRE·03:44 PM
Description
Data Sourced
04:00 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0195?
CVE-2010-0195 has been assigned a CVSS score indicating that it is a critical vulnerability, allowing remote code execution.
2
How do I fix CVE-2010-0195?
To fix CVE-2010-0195, users should update to Adobe Acrobat and Reader version 9.3.2 or 8.2.2 and later.
3
Which versions of Adobe Reader are affected by CVE-2010-0195?
CVE-2010-0195 affects Adobe Reader and Acrobat 9.x versions before 9.3.2 and 8.x versions before 8.2.2.
4
What types of attacks can exploit CVE-2010-0195?
CVE-2010-0195 can be exploited by attackers to execute arbitrary code on the victim's machine through specially crafted PDF files.
5
Is CVE-2010-0195 a vulnerability that affects only Windows operating systems?
No, CVE-2010-0195 affects Adobe Reader and Acrobat on both Windows and Mac OS X platforms.